[lug] SSH Probing Solution using IPTables

Sean Reifschneider jafo at tummy.com
Tue Oct 4 10:25:01 MDT 2005


On Mon, Sep 26, 2005 at 08:15:49PM -0600, George Sexton wrote:
>If this is a new connection, and it hasn't exceeded the recent source IP
>connection limit, then it is accepted.

Not sure why I missed that, I think I noticed it at one point...

>I pushed 500K Bytes/second through the machine with that firewall. It didn't
>seem to impact things that much.

Yeah, it's unlikely to.  I ran a test with 65k rules in a table once and it
worked fine, a couple of rules isn't likely to impact it.

Thanks,
Sean
-- 
 /home is where your .heart is.  -- Sean Reifschneider, 1999
Sean Reifschneider, Member of Technical Staff <jafo at tummy.com>
tummy.com, ltd. - Linux Consulting since 1995: Ask me about High Availability
      Back off man. I'm a scientist.   http://HackingSociety.org/




More information about the LUG mailing list